Edit tour

Windows Analysis Report
http://mtowner.com

Overview

General Information

Sample URL:http://mtowner.com
Analysis ID:1672198
Infos:

Detection

Score:0
Range:0 - 100
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 6284 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6476 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2024,i,4018944160567379143,18077518364261050696,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2096 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7164 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://mtowner.com" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 194.87.31.237:443 -> 192.168.2.16:49705 version: TLS 1.2
Source: unknownHTTPS traffic detected: 194.87.31.237:443 -> 192.168.2.16:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.178.49.196:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 84.201.221.20
Source: unknownTCP traffic detected without corresponding DNS query: 84.201.221.20
Source: unknownTCP traffic detected without corresponding DNS query: 72.247.234.254
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.190.194
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.190.194
Source: unknownTCP traffic detected without corresponding DNS query: 72.247.234.254
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: mtowner.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: mtowner.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mtowner.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: mtowner.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 23 Apr 2025 15:15:41 GMTServer: Apache/2.4.52 (Ubuntu)Content-Length: 274Connection: closeContent-Type: text/html; charset=iso-8859-1
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49673
Source: unknownNetwork traffic detected: HTTP traffic on port 49694 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49694
Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTPS traffic detected: 194.87.31.237:443 -> 192.168.2.16:49705 version: TLS 1.2
Source: unknownHTTPS traffic detected: 194.87.31.237:443 -> 192.168.2.16:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.178.49.196:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: classification engineClassification label: clean0.win@23/4@6/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2024,i,4018944160567379143,18077518364261050696,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2096 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://mtowner.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2024,i,4018944160567379143,18077518364261050696,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2096 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1672198 URL: http://mtowner.com Startdate: 23/04/2025 Architecture: WINDOWS Score: 0 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.16, 138, 443, 49611 unknown unknown 5->13 10 chrome.exe 5->10         started        process4 dnsIp5 15 www.google.com 192.178.49.196, 443, 49712, 49723 GOOGLEUS United States 10->15 17 mtowner.com 194.87.31.237, 443, 49705, 49706 ASBAXETNRU Russian Federation 10->17

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://mtowner.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://mtowner.com/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
192.178.49.196
truefalse
    high
    mtowner.com
    194.87.31.237
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://mtowner.com/favicon.icofalse
      • Avira URL Cloud: safe
      unknown
      https://mtowner.com/false
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        192.178.49.196
        www.google.comUnited States
        15169GOOGLEUSfalse
        194.87.31.237
        mtowner.comRussian Federation
        49392ASBAXETNRUfalse
        IP
        192.168.2.16
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1672198
        Start date and time:2025-04-23 17:15:05 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 21s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:defaultwindowsinteractivecookbook.jbs
        Sample URL:http://mtowner.com
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:14
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean0.win@23/4@6/3
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 192.178.49.174, 192.178.49.195, 74.125.137.84, 142.250.69.14, 192.178.49.163, 142.250.69.3, 172.202.163.200, 184.29.183.29
        • Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtOpenFile calls found.
        • VT rate limit hit for: http://mtowner.com
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:ASCII text, with no line terminators
        Category:downloaded
        Size (bytes):9
        Entropy (8bit):3.169925001442312
        Encrypted:false
        SSDEEP:3:wFSuL:wZL
        MD5:35D56D565628F654CCEFAEE619BA9728
        SHA1:4CB2C207D5A9BB582AA3DDD06786D1AFA0D8BADA
        SHA-256:B22550984AE425E3EA0ED0FCC3AD554A42C7206BCC9CEEF5CC72528463560EFD
        SHA-512:76DA290B4AD80FD6FC9CF9C155110F11A9EEC503C5B9C4A306EEE060C08B4192A1D59BA437D027AB6C1559A9BF92B63DCE8823C2A63CA871175B8B2DC1C7DED5
        Malicious:false
        Reputation:low
        URL:https://mtowner.com/
        Preview:It works.
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text
        Category:downloaded
        Size (bytes):274
        Entropy (8bit):5.199814983438777
        Encrypted:false
        SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoIRCwdExBFm8oD:J0+oxBeRmR9etdzRxGezHtdf8+
        MD5:C0B627F00C73171731BB84149A9A9663
        SHA1:187B5502E9F3C41971B1EF5145290361B37FE83E
        SHA-256:BDBE61F9CAEB9752F6959FB5C524EADBCBE590F24EA77B8282E1ECB03C4C1F34
        SHA-512:1F30B32BAD1E5D1F3DBA9898AC30056B24641CEB4E81FC2F70AEDECC95D45529825E7E04732AF4E8A8849C23A8EECEFF91C0FFF98863E5F1BA6C48B0335457E9
        Malicious:false
        Reputation:low
        URL:https://mtowner.com/favicon.ico
        Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<hr>.<address>Apache/2.4.52 (Ubuntu) Server at mtowner.com Port 443</address>.</body></html>.
        No static file info

        Download Network PCAP: filteredfull

        • Total Packets: 52
        • 443 (HTTPS)
        • 80 (HTTP)
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Apr 23, 2025 17:15:38.624130964 CEST49705443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:38.624224901 CEST44349705194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:38.624350071 CEST49705443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:38.624541998 CEST49705443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:38.624563932 CEST44349705194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:38.643188000 CEST4970680192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:38.643336058 CEST4970780192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:38.899524927 CEST49705443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:38.899974108 CEST49708443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:38.899998903 CEST44349708194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:38.900067091 CEST49708443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:38.900201082 CEST49708443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:38.900209904 CEST44349708194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:38.911542892 CEST8049706194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:38.911595106 CEST4970680192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:38.911648035 CEST8049707194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:38.911700010 CEST4970780192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:38.940284967 CEST44349705194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:39.174309969 CEST44349705194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:39.174434900 CEST49705443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:39.174458981 CEST49705443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:39.448565006 CEST44349708194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:39.448652029 CEST49708443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:39.449790001 CEST49708443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:39.449800968 CEST44349708194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:39.450018883 CEST44349708194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:39.450329065 CEST49708443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:39.492271900 CEST44349708194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:39.987339020 CEST44349708194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:39.987421036 CEST44349708194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:39.987500906 CEST49708443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:39.988291979 CEST49708443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:39.988306046 CEST44349708194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:40.051949978 CEST49710443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:40.051987886 CEST44349710194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:40.052117109 CEST49710443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:40.052264929 CEST49710443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:40.052274942 CEST44349710194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:40.596247911 CEST44349710194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:40.596568108 CEST49710443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:40.596601009 CEST44349710194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:40.596724033 CEST49710443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:40.596729040 CEST44349710194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:41.143693924 CEST44349710194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:41.143764019 CEST44349710194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:41.143822908 CEST49710443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:41.144288063 CEST49710443192.168.2.16194.87.31.237
        Apr 23, 2025 17:15:41.144299984 CEST44349710194.87.31.237192.168.2.16
        Apr 23, 2025 17:15:42.760914087 CEST49712443192.168.2.16192.178.49.196
        Apr 23, 2025 17:15:42.760951042 CEST44349712192.178.49.196192.168.2.16
        Apr 23, 2025 17:15:42.761035919 CEST49712443192.168.2.16192.178.49.196
        Apr 23, 2025 17:15:42.761164904 CEST49712443192.168.2.16192.178.49.196
        Apr 23, 2025 17:15:42.761177063 CEST44349712192.178.49.196192.168.2.16
        Apr 23, 2025 17:15:43.082128048 CEST44349712192.178.49.196192.168.2.16
        Apr 23, 2025 17:15:43.082254887 CEST49712443192.168.2.16192.178.49.196
        Apr 23, 2025 17:15:43.083324909 CEST49712443192.168.2.16192.178.49.196
        Apr 23, 2025 17:15:43.083333015 CEST44349712192.178.49.196192.168.2.16
        Apr 23, 2025 17:15:43.083817959 CEST44349712192.178.49.196192.168.2.16
        Apr 23, 2025 17:15:43.127458096 CEST49712443192.168.2.16192.178.49.196
        Apr 23, 2025 17:15:47.250562906 CEST49673443192.168.2.162.23.227.208
        Apr 23, 2025 17:15:47.250614882 CEST443496732.23.227.208192.168.2.16
        Apr 23, 2025 17:15:51.575762987 CEST49671443192.168.2.16204.79.197.203
        Apr 23, 2025 17:15:51.877531052 CEST49671443192.168.2.16204.79.197.203
        Apr 23, 2025 17:15:52.483561039 CEST49671443192.168.2.16204.79.197.203
        Apr 23, 2025 17:15:53.110253096 CEST44349712192.178.49.196192.168.2.16
        Apr 23, 2025 17:15:53.110316992 CEST44349712192.178.49.196192.168.2.16
        Apr 23, 2025 17:15:53.110394001 CEST49712443192.168.2.16192.178.49.196
        Apr 23, 2025 17:15:53.697413921 CEST49671443192.168.2.16204.79.197.203
        Apr 23, 2025 17:15:54.019285917 CEST49712443192.168.2.16192.178.49.196
        Apr 23, 2025 17:15:54.019323111 CEST44349712192.178.49.196192.168.2.16
        Apr 23, 2025 17:15:56.105443001 CEST49671443192.168.2.16204.79.197.203
        Apr 23, 2025 17:16:00.000696898 CEST49679443192.168.2.1652.182.143.211
        Apr 23, 2025 17:16:00.303481102 CEST49679443192.168.2.1652.182.143.211
        Apr 23, 2025 17:16:00.908444881 CEST49679443192.168.2.1652.182.143.211
        Apr 23, 2025 17:16:00.909674883 CEST49671443192.168.2.16204.79.197.203
        Apr 23, 2025 17:16:02.119451046 CEST49679443192.168.2.1652.182.143.211
        Apr 23, 2025 17:16:04.531428099 CEST49679443192.168.2.1652.182.143.211
        Apr 23, 2025 17:16:09.337486982 CEST49679443192.168.2.1652.182.143.211
        Apr 23, 2025 17:16:10.519505024 CEST49671443192.168.2.16204.79.197.203
        Apr 23, 2025 17:16:18.950563908 CEST49679443192.168.2.1652.182.143.211
        Apr 23, 2025 17:16:22.753799915 CEST4969380192.168.2.1684.201.221.20
        Apr 23, 2025 17:16:22.760310888 CEST804969384.201.221.20192.168.2.16
        Apr 23, 2025 17:16:22.760380983 CEST4969380192.168.2.1684.201.221.20
        Apr 23, 2025 17:16:22.901273012 CEST804969384.201.221.20192.168.2.16
        Apr 23, 2025 17:16:42.673891068 CEST49723443192.168.2.16192.178.49.196
        Apr 23, 2025 17:16:42.673985958 CEST44349723192.178.49.196192.168.2.16
        Apr 23, 2025 17:16:42.674134970 CEST49723443192.168.2.16192.178.49.196
        Apr 23, 2025 17:16:42.674274921 CEST49723443192.168.2.16192.178.49.196
        Apr 23, 2025 17:16:42.674319029 CEST44349723192.178.49.196192.168.2.16
        Apr 23, 2025 17:16:42.988873005 CEST44349723192.178.49.196192.168.2.16
        Apr 23, 2025 17:16:42.989188910 CEST49723443192.168.2.16192.178.49.196
        Apr 23, 2025 17:16:42.989223003 CEST44349723192.178.49.196192.168.2.16
        Apr 23, 2025 17:16:52.978255987 CEST44349723192.178.49.196192.168.2.16
        Apr 23, 2025 17:16:52.978323936 CEST44349723192.178.49.196192.168.2.16
        Apr 23, 2025 17:16:52.978377104 CEST49723443192.168.2.16192.178.49.196
        Apr 23, 2025 17:16:53.011173010 CEST49723443192.168.2.16192.178.49.196
        Apr 23, 2025 17:16:53.011214018 CEST44349723192.178.49.196192.168.2.16
        Apr 23, 2025 17:17:14.694060087 CEST4969580192.168.2.1672.247.234.254
        Apr 23, 2025 17:17:14.694060087 CEST49694443192.168.2.1620.190.190.194
        Apr 23, 2025 17:17:14.835268021 CEST4434969420.190.190.194192.168.2.16
        Apr 23, 2025 17:17:14.835375071 CEST49694443192.168.2.1620.190.190.194
        Apr 23, 2025 17:17:14.841275930 CEST804969572.247.234.254192.168.2.16
        Apr 23, 2025 17:17:14.841360092 CEST4969580192.168.2.1672.247.234.254
        TimestampSource PortDest PortSource IPDest IP
        Apr 23, 2025 17:15:37.930414915 CEST53496111.1.1.1192.168.2.16
        Apr 23, 2025 17:15:38.025680065 CEST53653741.1.1.1192.168.2.16
        Apr 23, 2025 17:15:38.462941885 CEST5208253192.168.2.161.1.1.1
        Apr 23, 2025 17:15:38.463156939 CEST5698853192.168.2.161.1.1.1
        Apr 23, 2025 17:15:38.471229076 CEST5401153192.168.2.161.1.1.1
        Apr 23, 2025 17:15:38.471784115 CEST5598153192.168.2.161.1.1.1
        Apr 23, 2025 17:15:38.621625900 CEST53559811.1.1.1192.168.2.16
        Apr 23, 2025 17:15:38.623544931 CEST53540111.1.1.1192.168.2.16
        Apr 23, 2025 17:15:38.639333963 CEST53520821.1.1.1192.168.2.16
        Apr 23, 2025 17:15:38.642431021 CEST53569881.1.1.1192.168.2.16
        Apr 23, 2025 17:15:39.098345041 CEST53511371.1.1.1192.168.2.16
        Apr 23, 2025 17:15:42.619210005 CEST5367053192.168.2.161.1.1.1
        Apr 23, 2025 17:15:42.619363070 CEST5955853192.168.2.161.1.1.1
        Apr 23, 2025 17:15:42.759603024 CEST53536701.1.1.1192.168.2.16
        Apr 23, 2025 17:15:42.760087967 CEST53595581.1.1.1192.168.2.16
        Apr 23, 2025 17:15:56.140391111 CEST53537701.1.1.1192.168.2.16
        Apr 23, 2025 17:16:15.116616011 CEST53556761.1.1.1192.168.2.16
        Apr 23, 2025 17:16:37.911000013 CEST53590441.1.1.1192.168.2.16
        Apr 23, 2025 17:16:37.989602089 CEST53539221.1.1.1192.168.2.16
        Apr 23, 2025 17:16:41.357959986 CEST53546091.1.1.1192.168.2.16
        Apr 23, 2025 17:16:57.615021944 CEST138138192.168.2.16192.168.2.255
        Apr 23, 2025 17:17:08.439161062 CEST53502311.1.1.1192.168.2.16
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 23, 2025 17:15:38.462941885 CEST192.168.2.161.1.1.10x71a9Standard query (0)mtowner.comA (IP address)IN (0x0001)false
        Apr 23, 2025 17:15:38.463156939 CEST192.168.2.161.1.1.10x3b5eStandard query (0)mtowner.com65IN (0x0001)false
        Apr 23, 2025 17:15:38.471229076 CEST192.168.2.161.1.1.10xc5b1Standard query (0)mtowner.comA (IP address)IN (0x0001)false
        Apr 23, 2025 17:15:38.471784115 CEST192.168.2.161.1.1.10xf6a0Standard query (0)mtowner.com65IN (0x0001)false
        Apr 23, 2025 17:15:42.619210005 CEST192.168.2.161.1.1.10x6935Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Apr 23, 2025 17:15:42.619363070 CEST192.168.2.161.1.1.10x12c0Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 23, 2025 17:15:38.623544931 CEST1.1.1.1192.168.2.160xc5b1No error (0)mtowner.com194.87.31.237A (IP address)IN (0x0001)false
        Apr 23, 2025 17:15:38.639333963 CEST1.1.1.1192.168.2.160x71a9No error (0)mtowner.com194.87.31.237A (IP address)IN (0x0001)false
        Apr 23, 2025 17:15:42.759603024 CEST1.1.1.1192.168.2.160x6935No error (0)www.google.com192.178.49.196A (IP address)IN (0x0001)false
        Apr 23, 2025 17:15:42.760087967 CEST1.1.1.1192.168.2.160x12c0No error (0)www.google.com65IN (0x0001)false
        • mtowner.com
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.1649708194.87.31.2374436476C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-04-23 15:15:39 UTC661OUTGET / HTTP/1.1
        Host: mtowner.com
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        2025-04-23 15:15:39 UTC166INHTTP/1.1 200 OK
        Date: Wed, 23 Apr 2025 15:15:39 GMT
        Server: Apache/2.4.52 (Ubuntu)
        Content-Length: 9
        Connection: close
        Content-Type: text/html; charset=UTF-8
        2025-04-23 15:15:39 UTC9INData Raw: 49 74 20 77 6f 72 6b 73 2e
        Data Ascii: It works.


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.1649710194.87.31.2374436476C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-04-23 15:15:40 UTC585OUTGET /favicon.ico HTTP/1.1
        Host: mtowner.com
        Connection: keep-alive
        sec-ch-ua-platform: "Windows"
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://mtowner.com/
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        2025-04-23 15:15:41 UTC180INHTTP/1.1 404 Not Found
        Date: Wed, 23 Apr 2025 15:15:41 GMT
        Server: Apache/2.4.52 (Ubuntu)
        Content-Length: 274
        Connection: close
        Content-Type: text/html; charset=iso-8859-1
        2025-04-23 15:15:41 UTC274INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 32 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 6d 74 6f 77 6e 65 72 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65
        Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><hr><address>Apache/2.4.52 (Ubuntu) Server at mtowner.com Port 443</addre


        050100s020406080100

        Click to jump to process

        050100s0.0050100MB

        Click to jump to process

        Target ID:0
        Start time:11:15:35
        Start date:23/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff77eaf0000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:1
        Start time:11:15:36
        Start date:23/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2024,i,4018944160567379143,18077518364261050696,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2096 /prefetch:3
        Imagebase:0x7ff77eaf0000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:11:15:37
        Start date:23/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://mtowner.com"
        Imagebase:0x7ff77eaf0000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

        No disassembly